HITRUST/AMA Launch Initiative to Help Small Healthcare Providers with HIPAA Compliance
HITRUST has announced it has partnered with the American Medical Association (AMA) for a new initiative that will help small healthcare providers with HIPAA compliance, cybersecurity, and cyber risk management. Small healthcare providers can be particularly vulnerable to cyberattacks, as they typically lack the resources to devote to cybersecurity and do not tend to have the budgets available to hire skilled cybersecurity staff. This week has underscored the need for small practices to improve their cybersecurity defenses, with the announcement of two cyberattacks on small healthcare providers by the hacking group TheDarkOverlord. Recent ransomware attacks have also shown that healthcare organizations of all sizes are likely to be attacked. Organizations of all sizes must practice good cyber hygiene and have the right defenses in place to improve resilience against ever changing cyber threats. HITRUST and AMA will be hosting 2-hour workshops where physicians and other healthcare staff will be educated on key areas of risk management, HIPAA compliance, and cybersecurity, with the...
SonicWall Responds to Increasing Cyber Threats with Major Expansion of Cybersecurity Solutions
The massive rise in new ransomware and malware variants, and the increasing sophistication of cyberattacks on businesses have been accompanied by unprecedented innovation at SonicWall, which has rapidly expanded its range of cybersecurity solutions in response to the growing demand for more powerful solutions. SonicWall has now released its new SonicOS operating system, which includes more than 50 new features to enhance security and is the biggest customer-driven release in the history of the company. The SonicOS (v6.5) powers SonicWall’s Automated Real-Time Breach Detection and Prevention Platform. The new release has enhanced threat API capabilities that allow businesses to automate security systems and incorporate third-party intelligence feeds. New wireless features improve connectivity for an increasingly mobile workforce and help security teams enforce their policies across the entire organization. Advanced networking and connectivity capabilities have also been introduced to provide uninterrupted threat protection for connected networks of all types and sizes. The new...
The Benefits of Using Blockchain for Medical Records
Blockchain is perhaps best known for keeping cryptocurrency transactions secure, but what about using blockchain for medical records? Could blockchain help to improve healthcare data security? The use of blockchain for medical records is still in its infancy, but there are clear security benefits that could help to reduce healthcare data breaches while making it far easier for health data to be shared between providers and accessed by patients. Currently, the way health records are stored and shared leaves much to be desired. The system is not efficient, there are many roadblocks that prevent the sharing of data, and patients’ health data is not always stored by a single healthcare provider – instead, a patient’s full health history is fragmented and spread across multiple providers’ systems. Not only does this make it difficult for health data to be amalgamated, but it also leaves data vulnerable to theft. When data is split between multiple providers and their business associates, there is considerable potential for a breach. The Health Insurance Portability and Accountability...
Another Healthcare Organization Attacked by The Dark Overlord
Following a couple of months of relative quiet, the hacking group TheDarkOverlord has announced another successful attack on a U.S. healthcare provider, Mass-based SMART Physical Therapy (SMART PT). The hack reportedly occurred on September 13, 2017, with the announcement of the data theft disclosed by TDO on Twitter on Friday 22, 2017. No mention was made about how access to the data was gained, although it was confirmed to databreaches.net that the attack took advantage of the use of weak passwords. The entire database of patients was reportedly stolen. Databreaches.net was provided with the patient database and has confirmed the authenticity of the attack. The database contained a wide range of information on 16,428 patients, including contact information, dates of birth and Social Security numbers. This was an extortion attempt and a demand for payment in Bitcoin was reportedly sent to SMART PT, although no payment has been made, nor will it be. SMART PT spokesperson Joanne Ponte confirmed to databreaches.net that they refuse to communicate with criminals and give in to the...
OIG Discovers Multiple Security Vulnerabilities in Alabama’s Medicaid Management Information System
The HHS’ Office of Inspector General (OIG) has conducted a review of Alabama’s Medicaid data and information systems to ascertain whether the state was in compliance with federal regulations. The review covered the Medicaid Management Information System (MMIS) and associated policies and procedures. OIG also conducted a vulnerability scan on networked devices, databases, websites, and servers to identify vulnerabilities that could potentially be exploited to gain access to systems and sensitive data. The audit revealed Alabama’s MMIS had multiple vulnerabilities that could potentially be exploited by hackers to gain access to its systems and Medicaid data. Alabama had adopted a security program for its MMIS, although several vulnerabilities had been allowed to persist. OIG said in its report, the vulnerabilities were “collectively and, in some cases, individually significant.” OIG did not uncover any evidence to suggest the vulnerabilities had already been exploited, although the vulnerabilities did place the integrity of the state Medicaid program at risk. By exploiting the...



